SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for protected shared notes does not rotate the session identifier after successful authentication, allowing session fixation. An attacker who can o
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Syslifters | sysreptor | < 2026.68 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Syslifters | sysreptor | < 2026.68 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81180 | 8.8 HIGH | SysReptor: Authenticated RCE by insecure image processing |
| CVE-2026-81179 | 8.1 HIGH | SysReptor: Host header injection might allow account takeover |
| CVE-2026-81182 | 4.2 MEDIUM | SysReptor: Unauthorized file disclosure by broken access control in writable shared notes |
| CVE-2026-81178 | 3.5 LOW | SysReptor: Anonymous note-share link discloses project member identities and non-shared no |
No comments yet